CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-10
jvalenzuela jvalenzuela is offline
Junior Member
 
Join Date: 2007-01-16
Posts: 29
Rep Power: 0
jvalenzuela has an average reputation (10+)
Default Cannot ssh to a cisco pix

Hello

I have already changed a SmartConsole over Solaris to Secure Platform. Before this change, we were able to access a Cisco Pix via telnet. Since SP does not have telnet we tried to access using ssh(this is allowed on the pix) but we are not able to. I got the following information with the debug option.

[Expert@console]# ssh -v 192.168.6.11
OpenSSH_3.6.1p2, SSH protocols 1.5/2.0, OpenSSL 0x0090701f
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Applying options for *
debug1: Rhosts Authentication disabled, originating port will not be trusted.
debug1: Connecting to 192.168.6.11 [192.168.6.11] port 22.
debug1: Connection established.
debug1: identity file /root/.ssh/identity type -1
debug1: identity file /root/.ssh/id_rsa type -1
debug1: identity file /root/.ssh/id_dsa type -1
debug1: Remote protocol version 1.5, remote software version Cisco-1.25
debug1: no match: Cisco-1.25
debug1: Local version string SSH-1.5-OpenSSH_3.6.1p2
debug1: Waiting for server public key.
debug1: Received server public key (768 bits) and host key (1024 bits).
debug1: Host '192.168.6.11' is known and matches the RSA1 host key.
debug1: Found key in /root/.ssh/known_hosts:3
Selected cipher type <unknown> not supported by server.
debug1: Calling cleanup 0x8062240(0x0)
[Expert@console]#

Any idea to solve this problem?
Reply With Quote
  #2 (permalink)  
Old 2007-02-10
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Cannot ssh to a cisco pix

'Tis an old PIX supporting only DES encryption and not 3DES. It's also running SSHv1. You should upgrade into at least the latter 6.3 PIX code and get a 3des license for it (I assume upgrading the PIX to an UTM-1 isn't an option you)
Reply With Quote
  #3 (permalink)  
Old 2007-02-11
jvalenzuela jvalenzuela is offline
Junior Member
 
Join Date: 2007-01-16
Posts: 29
Rep Power: 0
jvalenzuela has an average reputation (10+)
Default Re: Cannot ssh to a cisco pix

I thought it was something about the encryption. However, I'm not the PIX administrator. I just can suggest the upgrade.

I'll try using DES encryption.

Thx

Jorge
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:08.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0